Exchange Server Forums

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

PoP3 security

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [Microsoft Exchange 2003] >> Server Security >> PoP3 security Page: [1]
Login
Message << Older Topic   Newer Topic >>
Limited time MSExchange.org offer! -- 1.Sep.2008 1:00:00 PM
TechGenix and SolarWinds have partnered to provide free copies of SolarWinds Exchange Monitor to all visitors who join the MSExchange.org Forums. SolarWinds Exchange Monitor is a handy desktop dashboard that continuously monitors Microsoft Exchange to deliver real-time insight into Exchange services, mail queue sizes, and host server health. Learn more about Exchange Monitor and the free offer!
PoP3 security - 18.Sep.2003 10:55:00 AM   
Tom Decaluwé

 

Posts: 174
Joined: 18.Sep.2003
From: Belgium
Status: offline
Hi, I have a question on security regarding Active Directory / exchange and pop3.

Situation is simpel, i have an win2k domain with an Exchange2k. At the office we use mapi or whatever the standard outlook <=> exchange protocol is called. This securely authenticates my users to the exchange system if i'm not mistaken.

Now form there homes i setup the system so they can use pop3 to the server as most of them are using Outlook express or other simpel mail clients on a mix of win/mac/linux clients. I made mini manuals so they now how to apply leave messages on server so no big issue there. All is fine with this system except that i'm having security thoughts.

When using pop3 the are acutally authenticating using there AD username and password that is sent in clear text and thus can easily be sniffed.

What are your thoughts about this? One password for office and home is nice but than again i don't link the idea of sending my domain paswords over the internet. Especially now that we are thinking of publishing a Terminal server on there web. Siffing out a pop3 would give anyone access to our TS server.

Question is:

1) Can you split the passwords on exchange => so for internal use they have there domain paswords,... but give pop a different pasword are is the AD password always also going to be PoP3 password?

2) what whould you propose to do towards this issue? Stop using pop3 and switching to OWA over SSL? Or should ik stop PoP3 and move to imap/mapi for secure login?

Sorry for the long post but i was wondering what you experts think about this issue?

kind regards,

Tom
Post #: 1
RE: PoP3 security - 18.Sep.2003 10:57:00 AM   
Tom Decaluwé

 

Posts: 174
Joined: 18.Sep.2003
From: Belgium
Status: offline
Oops and now i see i'm in the 2003 forum, sorry about this but i can't move the message and cross posting is not my thing so i'll leave it here unless one of the admins can move it for me.

Thx

Tom

(in reply to Tom Decaluwé)
Post #: 2
RE: PoP3 security - 18.Sep.2003 12:05:00 PM   
marc2003

 

Posts: 82
Joined: 25.May2003
From: england
Status: offline
i'm no expert but i believe you can set up ssl for pop3 in exchange 2000. goto the properties of the pop3 virtual server in esm. then select the access tab. from the options here and the help files you should be able to work out how to install a certificate and make changes to run pop3 over ssl.

[ September 18, 2003, 01:56 PM: Message edited by: marc2003 ]

(in reply to Tom Decaluwé)
Post #: 3
RE: PoP3 security - 18.Sep.2003 11:28:00 PM   
samuelss

 

Posts: 4
Joined: 8.Sep.2003
From: london
Status: offline
Hi Tom DecaluwT

This may be what you need to help you out.

http://www.tacteam.net/isaserverorg/exchangekit/2003securepop3/2003securepop3.htm

Thanks.

sam

(in reply to Tom Decaluwé)
Post #: 4
RE: PoP3 security - 19.Sep.2003 1:07:00 PM   
Tom Decaluwé

 

Posts: 174
Joined: 18.Sep.2003
From: Belgium
Status: offline
Thanks for the link and the tip. It's exactly what i needed.

cheerz

Tom

(in reply to Tom Decaluwé)
Post #: 5

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [Microsoft Exchange 2003] >> Server Security >> PoP3 security Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts